WooCommerce Subscription < 9.1.0 - Unauthenticated PHP Object Injection
medium
The WooCommerce Subscription plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 9.1.0 (exclusive) via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this...
- CVSS:
- 5.3
- Affected:
- up to 9.1.0
- Fixed in:
- 9.1.0
- Disclosed:
- Aug 14, 2026
CVE-2026-18391 on NVD →
WooCommerce Subscriptions [woocommerce-subscriptions] < 5.8.0
unknown
[en] Missing Authorization vulnerability in Woo WooCommerce Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Subscriptions: from n/a before 5.8.0.
- Affected:
- up to 5.8.0
- Fixed in:
- 5.8.0
- Disclosed:
- Dec 31, 2024
CVE-2023-50850 on NVD →
WooCommerce Subscriptions < 5.8.0 - Missing Authorization
medium
The WooCommerce Subscriptions plugin for WordPress is vulnerable to unauthorized access of data or modification of data due to a missing capability check on an unknown low-severity function in versions up to 5.8.0. This makes it possible for authenticated attackers, with contributor-level access and above, to make use...
- CVSS:
- 4.3
- Affected:
- up to 5.8.0
- Fixed in:
- 5.8.0
- Disclosed:
- Jan 17, 2024
CVE-2023-50850 on NVD →
WooCommerce Subscriptions [woocommerce-subscriptions] < 5.1.3
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a through 5.1.2.
- Affected:
- up to 5.1.3
- Fixed in:
- 5.1.3
- Disclosed:
- Dec 20, 2023
CVE-2023-35914 on NVD →
WooCommerce Subscription < 4.6.0 - Cross-Site Request Forgery
medium
The WooCommerce Subscription for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and not including, 4.6.0. This is due to missing or incorrect nonce validation when suspending or canceling subscriptions. This makes it possible for unauthenticated attackers to change arbitrary subscriptions via...
- CVSS:
- 4.3
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.0
- Disclosed:
- Sep 11, 2023
WooCommerce Subscriptions [woocommerce-subscriptions] < 4.6.0
unknown
The WooCommerce Subscription for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and not including, 4.6.0. This is due to missing or incorrect nonce validation when suspending or canceling subscriptions. This makes it possible for unauthenticated attackers to change arbitrary subscriptions via...
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.0
- Disclosed:
- Sep 11, 2023
WooCommerce Subscriptions <= 5.1.2 - Missing Authorization to Insecure Direct Object Reference
medium
The WooCommerce Subscriptions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown unction in versions up to, and including, 5.1.2. This makes it possible for unauthenticated attackers to access or modify information by passing in a user-conttrolled par...
- CVSS:
- 6.5
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- Jun 19, 2023
CVE-2023-35914 on NVD →
WooCommerce Subscriptions [woocommerce-subscriptions] < 2.6.3
unknown
[en] Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Jul 23, 2020
CVE-2019-18834 on NVD →
WooCommerce Subscriptions <= 3.0.2 - Cross-Site Request Forgery
high
The WooCommerce Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.2. This is due to incorrect nonce validation on the view-subscription functionality. This makes it possible for unauthenticated attackers to modify any user's subscription status via a fo...
- CVSS:
- 8.3
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Apr 2, 2020
WooCommerce Subscriptions [woocommerce-subscriptions] < 3.0.3
unknown
The WooCommerce Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.2. This is due to incorrect nonce validation on the view-subscription functionality. This makes it possible for unauthenticated attackers to modify any user's subscription status via a fo...
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Apr 2, 2020
WooCommerce Subscriptions < 2.6.3 - Stored Cross-Site Scripting
medium
Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.
- CVSS:
- 6.1
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Mar 11, 2019
CVE-2019-18834 on NVD →
WooCommerce Subscriptions [woocommerce-subscriptions] < 3.0.3
unknown
During a blog assessment, we identified a CSRF issue in the Woocommerce Subscriptions plugin, which could allow attackers to cancel and re-activate a logged in user's subscription. Even though the _wpnonce parameter was needed in the request, its value was not verified, allowing an empty value to be honoured.
K...
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
WooCommerce Subscriptions [woocommerce-subscriptions] < 4.6.0
unknown
The plugin does not have CSRF check when suspending and activating subscriptions, which could allow attackers to make a logged in admin suspend or activate arbitrary subscription via a CSRF attack
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.0
WooCommerce Subscriptions [woocommerce-subscriptions] < 4.6.0
unknown
The WooCommerce Subscription for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and not including, 4.6.0. This is due to missing or incorrect nonce validation when suspending or canceling subscriptions. This makes it possible for unauthenticated attackers to change arbitrary subscriptions via...
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database